CVE-2004-0574
Microsoft Windows NNTP Service (XPAT) - Denial of Service (MS04-036)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
El componente de Protocolo de Transferencia de Noticias de Red (NNTP) de Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, y Exchange Server 2003 permite a atacantes remtos ejecutar código de su elección mediante patrones XPAT, posiblemente relacionado con una validación de longitud inadecuada o un "búfer sin comprobar", conduciendo a desbordamientos de búfer basados en la pila y error de fuera por uno.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2004-06-15 CVE Reserved
- 2004-10-13 CVE Published
- 2004-10-16 First Exploit
- 2024-08-08 CVE Updated
- 2024-10-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (13)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/578 | 2004-10-16 |
URL | Date | SRC |
---|---|---|
http://www.kb.cert.org/vuls/id/203126 | 2020-04-09 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-036 | 2020-04-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2000 Search vendor "Microsoft" for product "Exchange Server" and version "2000" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2003 Search vendor "Microsoft" for product "Exchange Server" and version "2003" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | - | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Nt Search vendor "Microsoft" for product "Windows Nt" | 4.0 Search vendor "Microsoft" for product "Windows Nt" and version "4.0" | server |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2003 Search vendor "Microsoft" for product "Windows Server 2003" | r2 Search vendor "Microsoft" for product "Windows Server 2003" and version "r2" | - |
Affected
|